widgets.amung.us - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned widgets.amung.us and returned a suspicious verdict (score 45). The page resolved to 172.66.172.247 on Cloudflare, Inc. in US. 3 domains and 1 IP were contacted. 41 malware samples communicate with this URL. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://widgets.amung.us/classic.js - Domain: widgets.amung.us · IP: 172.66.172.247 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/x-javascript
- Scan tier: fast · observed 2026-08-21 14:08:36 UTC
Malware communicating with this URL (41)
These samples were observed contacting or being served from widgets.amung.us. Each links to its full analysis.
- 6b291a07958ccaefb0cb22910ca70f2120491a777386511858d24691dca72107 - referenced ·
6b291a07958ccaefb0cb22910ca70f21· first seen 2026-08-21 - df0eeb407fe5fbb2047fd9b936cde6df31600be25056dff3dcf07d3ba3ad7d7e - referenced ·
df0eeb407fe5fbb2047fd9b936cde6df· first seen 2026-08-21 - df05cdb875c8c739f4790ded50c1a5a9c6f775bdd704471f725e21582e38c4d3 - referenced ·
df05cdb875c8c739f4790ded50c1a5a9· first seen 2026-08-21 - df05cd3736dd18eb19d506b05d8290e05aa4ee725c0457830f55c6cac87919f9 - referenced ·
df05cd3736dd18eb19d506b05d8290e0· first seen 2026-08-21 - df053d4348143ccf30f9befff240c15a17be8fef855c5146726550917bd5fb44 - referenced ·
df053d4348143ccf30f9befff240c15a· first seen 2026-08-21 - e0da1271a9e432b1e26f41a5df95ac1a0dc3a4b6bbbe0fbbddf43f974976487f - referenced ·
e0da1271a9e432b1e26f41a5df95ac1a· first seen 2026-08-21 - 7f4c9279e62a5de10979a4f660f1dc7148cd47139a15b104bd911e8227d1d2bf - referenced ·
7f4c9279e62a5de10979a4f660f1dc71· first seen 2026-08-20 - 27c3c4e40b0472c7633c3c261bc01176a57fc3a5ca28cc417d1e955e6b5e39c6 - referenced ·
27c3c4e40b0472c7633c3c261bc01176· first seen 2026-08-20 - 7127907ce31aa75d8cfc81181ec46fb3d78036addde8025b959158979182f1f7 - referenced ·
7127907ce31aa75d8cfc81181ec46fb3· first seen 2026-08-20 - bd56432d8c49039f839455a8545e50c253bdccdde73ee8ecc10307716de32eca - referenced ·
bd56432d8c49039f839455a8545e50c2· first seen 2026-08-20 - bd5da4c68b012520a8d9998bd599c7a83005c9fc5b8a157f12a1a0004590eeaf - referenced ·
bd5da4c68b012520a8d9998bd599c7a8· first seen 2026-08-20 - fe52269516a6c33b031aa9e8964d227b7dc6e8953b79336d91c68e78d5b248fb - referenced ·
fe52269516a6c33b031aa9e8964d227b· first seen 2026-08-20 - 0691098f3a822470a776413b51823c7d6156cb5d2dbe5aaab394b1236913ee87 - referenced ·
0691098f3a822470a776413b51823c7d· first seen 2026-08-20 - 9c6fa584165193422ad9836f679d4a03b8f16ba0c2a373e310302e35e639b772 - referenced ·
9c6fa584165193422ad9836f679d4a03· first seen 2026-08-19 - 4235e231232c0707fc91c26792765a7e74749af5ddc0bb7e1ee18ef552bcf525 - referenced ·
4235e231232c0707fc91c26792765a7e· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (classic.js) is known suspicious in the corpus
- File download routed to the malware sandbox (classic.js)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.66.172.247 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- classic.js ·
f9ccdaa68ad30b653358a8e0f980095c
Observed indicators
- widgets.amung.us
- whos.amung.us
- t.dtscout.com
- 172.66.172.247
- http://widgets.amung.us/classic.js
- http://whos.amung.us/pingjs/?k=
- https://t.dtscout.com/i/?l=
Other scans of widgets.amung.us (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://jotamaria-cearense.blogspot.com/search - 24 Aug 2026 - unknown ·
http://fullpornolariizle.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-alecrim.blogspot.com/2012/10/blog-post.html - 23 Aug 2026 - suspicious ·
http://widgets.amung.us/colored.js - 23 Aug 2026 - unknown ·
http://jotamaria-ccdeassu.blogspot.com/search - 23 Aug 2026 - unknown ·
http://jotamaria-bmmossoro.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/2014/06/ex-governadores-do-ceara.html - 23 Aug 2026 - suspicious ·
http://widgets.amung.us/colored.js - 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/2014/11/blog-post_16.html
Questions about widgets.amung.us
- Is widgets.amung.us safe?
- No. MalwareAnalyzer scanned widgets.amung.us on 21 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with widgets.amung.us?
- 41 analysed samples communicate with this URL.
- How was widgets.amung.us checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of widgets.amung.us
Scanned on MalwareAnalyzer by Cyble · Open interactive scan